Vulnerability Description
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML and script code into a browser in the context of the vulnerable website.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atutor | Atutor | <= 2.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/atutor/ATutor/commit/9292360c8b3898d0990983269f110cef21729090Third Party Advisory
- https://github.com/atutor/ATutor/issues/135ExploitThird Party Advisory
- https://github.com/atutor/ATutor/commit/9292360c8b3898d0990983269f110cef21729090Third Party Advisory
- https://github.com/atutor/ATutor/issues/135ExploitThird Party Advisory
FAQ
What is CVE-2017-14981?
CVE-2017-14981 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could in...
How severe is CVE-2017-14981?
CVE-2017-14981 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14981?
Check the references section above for vendor advisories and patch information. Affected products include: Atutor Atutor.